Junglewise Threat Intelligence

CVE-2026-20215: ClamAV out-of-bounds write in 7z file format parser

CVE-2026-20215 · Severity: high · CVSS 7.5 · Published 2026-07-01

Technologies: Cisco Secure Endpoint Connector for Windows, Cisco Secure Endpoint Connector for Mac, Cisco Secure Endpoint Connector for Linux, Cisco ClamAV. Vendors: Cisco.

Executive brief

A vulnerability in the ClamAV antivirus engine, which is used to scan files for threats, could allow an attacker to crash the scanning service. By sending a specially crafted 7z compressed file, an attacker can cause the security software to stop functioning, potentially leaving the system unprotected or requiring a manual reboot. On Windows systems, this is particularly impactful as the scanning process runs with high privileges, which could lead to broader system instability.

Technical details

This vulnerability exists in the 7z file format parser of ClamAV due to improper boundary checks during the scanning of 7z content. An unauthenticated, remote attacker can exploit this by submitting a crafted 7z file, leading to an out-of-bounds buffer write. While the primary impact is the termination of the ClamAV scanning process (Denial of Service), memory corruption could potentially lead to other expanded impacts. On Windows-based Cisco Secure Endpoint Connectors, the process runs in a privileged context, making the impact more severe compared to Linux or Mac implementations. Cisco has released updates for affected Secure Endpoint products to address this issue.

Affected products

  • Cisco ClamAV
  • Cisco Secure Endpoint Connector for Windows Prior to 8.6.2
  • Cisco Secure Endpoint Connector for Linux Prior to 1.29.0
  • Cisco Secure Endpoint Connector for Mac Prior to 1.27.2

Timeline

  • 2026-07-01: advisory: Cisco published the security advisory.

References

Related threats